Логотип exploitDog
bind:CVE-2024-45813
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45813

Количество 4

Количество 4

redhat логотип

CVE-2024-45813

больше 1 года назад

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-45813

больше 1 года назад

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-rrr8-f88r-h8q6

больше 1 года назад

find-my-way has a ReDoS vulnerability in multiparametric routes

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-07779

больше 1 года назад

Уязвимость HTTP-маршрутизатора Find my Way, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании (ReDos)

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-45813

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45813

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-rrr8-f88r-h8q6

find-my-way has a ReDoS vulnerability in multiparametric routes

CVSS3: 7.5
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-07779

Уязвимость HTTP-маршрутизатора Find my Way, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании (ReDos)

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу